CVE-2026-93838 - SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx
Brief
CVE ID : CVE-2026-93838
Published : Sept. 18, 2026, 8:17 p. m.
- 38 minutes ago
Description : SGLang versions through 0.
- 20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments.
Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.
Severity: 8.2
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
